LEGAL

Privacy Policy

What personal data we process, for what purpose and on what legal basis; with whom we share it, how long we keep it, and how you can exercise your rights.

Last updated: August 6, 2026

1. Data controller

The data controller is [Ad Soyad / Ticaret Unvanı] ([T.C. Kimlik No / Vergi Kimlik No]), [Açık adres — mahalle, cadde, no, ilçe/il, posta kodu], Türkiye.

Contact: [email protected]

This notice is also prepared to satisfy the transparency obligation under Article 10 of the Turkish Personal Data Protection Law No. 6698 (“KVKK”). For individuals in the European Economic Area, the Operator also acts as controller within the meaning of the GDPR.

2. Categories of data processed

The following data is processed in connection with the Service:

Your IP address is evaluated only transiently in server memory for rate limiting to prevent abuse; it is not written persistently to the database. For visitor traffic measurement, IP addresses are not collected at all.
CategoryDataSource
Identity and contactEmail address and, if provided, nameDirectly from you, or from Google if you sign in with Google
Account securityIrreversible hash of your password (PBKDF2-SHA256), email verification status, password change timestamp, session cookieGenerated by the system
PreferencesInterface language, theme, notification settings, tour/onboarding stateFrom you
Workspace contentBrand name and domain, competitor names, monitored questions, brand facts, tags, workspace nameFrom you
Measurement outputResponse texts obtained from AI platforms, brand mentions, ranking, tone analysis, cited sources, scores, alerts, recommendations, audit resultsGenerated by the system
Team dataEmail addresses and roles of people you inviteFrom you
Subscription dataPlan, subscription status, period end date, subscription identifier at the payment providerFrom the payment provider
Integration secretsSlack webhook URL, Telegram bot token and chat identifier that you enter; irreversible hashes of your API keysFrom you
Visitor traffic (optional)Via the snippet you add to your site: browser/bot identifier (user-agent), path visited, referrer, source platform and timestampFrom your site’s visitors — IP addresses are NOT collected or stored

3. Purposes and legal bases

Where we rely on legitimate interests we carry out a balancing assessment, and you have the right to object to that processing.

PurposeKVKK Art. 5 basisGDPR Art. 6 basis
Creating your account, authenticating you and providing the ServiceNecessary for the conclusion or performance of a contractPerformance of a contract (b)
Managing subscriptions, billing and plan entitlementsPerformance of a contract; legal obligationPerformance of a contract (b); legal obligation (c)
Running your questions on AI platforms and analysing the resultsPerformance of a contractPerformance of a contract (b)
Sending alert, report and informational emailsPerformance of a contract; legitimate interestPerformance of a contract (b); legitimate interest (f)
Preventing abuse, fraud and security incidents (rate limiting, logging)Legitimate interestLegitimate interest (f)
Operating, debugging and improving the ServiceLegitimate interestLegitimate interest (f)
Statutory retention and responding to competent authoritiesLegal obligationLegal obligation (c)
Transfers to AI providers located abroadExplicit consent, or necessity for performance of a contract (see section 5)Performance of a contract (b) / Art. 49(1)(b)

4. Data sent to AI platforms

The core function of the Service is to send the questions you define to AI platforms. The content transferred to those platforms consists of: the question texts you define for monitoring; and, during the analysis stage, your brand name, your competitor names, the brand facts you enter, and the response text returned by the platform.

Your account details (email address, name, password, subscription information) are not sent to those platforms.

We strongly recommend that you do not write personal data, trade secrets or confidential information into question texts, as such content is by definition transmitted to third-party platforms.

You can manage which platforms are used from Settings › Platforms within the Service and disable any platform you choose. You may also disable AI-assisted analysis entirely.

5. International transfers

By reason of how the Service operates, certain data is transferred to service providers established outside Türkiye. The recipients, the data transferred and the purposes are set out below:

DeepSeek is established in the People’s Republic of China, which is not on the list of countries recognised as providing adequate protection under KVKK. If you do not wish this transfer to take place, you can disable the DeepSeek platform from Settings › Platforms, and no such transfer will occur.
RecipientCountryData transferredPurpose
OpenAIUSAQuestion texts, brand/competitor names, analysis promptsObtaining and analysing ChatGPT responses
AnthropicUSAQuestion texts, brand/competitor names, response textsObtaining Claude responses; analysis engine
xAIUSAQuestion textsObtaining Grok responses
GoogleUSAQuestion texts; email and name if you sign in with GoogleObtaining Gemini responses; authentication
DeepSeekPeople’s Republic of ChinaQuestion textsObtaining DeepSeek responses
CreemIreland / EUEmail address, subscription and payment dataPayment and billing (Merchant of Record)
Slack / Telegram (only if you configure it)USA / otherAlert textsNotifications through the channel you choose

6. Retention periods

When you delete your account, your data in the live system is erased immediately. Backups taken before deletion age out of rotation within at most 14 days of your request. Retention obligations arising from law (for example financial records) are reserved.

DataRetention
Account and profile dataFor as long as the account remains open; erased immediately on account deletion
Workspace content and measurement outputFor as long as the account remains open; erased together with all related records when the account or workspace is deleted
History shown in the dashboardDisplayed 7, 30 or 365 days retrospectively depending on your plan (data is not deleted earlier; only the display window is limited)
Visitor traffic recordsFor as long as the account remains open; erased when the workspace is deleted
Email verification and password reset codesStored as hashes; at most 24 hours and 1 hour respectively
Team invitations7 days (expire if unused)
Payment event records (duplicate protection)Retained in line with accounting and evidentiary obligations
Server logs (error and security records)Short-lived on the hosting infrastructure; kept free of personal data so far as practicable
BackupsTaken as automatically rotated snapshots of the entire server; older snapshots are deleted by the rotation within at most 14 days

7. Sharing of data

We do not sell or rent your personal data and we do not share it with third parties for advertising purposes.

Data is shared only: (i) with the service providers listed in section 5 that are necessary to provide the Service; (ii) with infrastructure providers such as hosting and email delivery; (iii) with integrations you configure on your own instruction (Slack, Telegram, shared report link); and (iv) in response to duly made requests from competent public authorities.

When you enable the report sharing link, anyone holding that link can view the report without signing in. The link contains only report sections; question texts, responses, settings and account data are not shared. You may regenerate or disable the link at any time.

8. Security measures

The principal technical and organisational measures we apply are:

No system can be absolutely secure. If you discover a vulnerability, please report it to [email protected]; we assess such reports in good faith and without delay.
  • Encryption of all traffic with TLS, with HSTS enforced.
  • Storage of passwords in irreversible form (PBKDF2-SHA256, 120,000 iterations, random salt); passwords are never held in readable form.
  • Session cookies protected with httpOnly, SameSite and, in production, Secure flags; invalidation of all prior sessions on password change.
  • Workspace-level data isolation and role-based access (owner / editor / viewer).
  • Rate limiting on sign-in, registration and other sensitive endpoints to throttle brute-force attempts.
  • Address validation against server-side request forgery (SSRF), blocking access to internal network and cloud metadata addresses.
  • Storage of API keys and invitation codes only as irreversible hashes.
  • Automated nightly database backups retained for 14 days.
  • No advertising or third-party analytics cookies whatsoever.

9. Your rights

Under Article 11 of the KVKK you have the right to apply to the data controller to: learn whether your personal data is processed; request information if it has been processed; learn the purpose of processing and whether it is used in accordance with that purpose; know the third parties to whom data is transferred domestically or abroad; request rectification if data is incomplete or inaccurate; request erasure or destruction; request that rectification, erasure and destruction be notified to third parties to whom data was transferred; object to a result adverse to you arising from analysis solely by automated systems; and claim compensation for loss suffered due to unlawful processing.

If the GDPR applies to you, you additionally have rights of access, rectification, erasure, restriction of processing, data portability and objection; the right to withdraw consent where processing is based on consent; and the right to lodge a complaint with a competent supervisory authority.

You can exercise several of these rights directly within the Service: export your data as CSV, update your account details, and permanently delete your account together with all your data.

Requests may be sent to [email protected] and are concluded within thirty (30) days at the latest. We may request additional information to verify the identity of the applicant.

10. Automated decisions and profiling

The Service does not produce decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Scores, recommendations and priority ratings within the Service are analytical outputs relating to your brand’s visibility and do not constitute an assessment of an individual.

11. Children’s data

The Service is not directed at persons under 18 and we do not knowingly process the personal data of persons under 18. If we learn that such data has been processed, it is deleted without delay.

12. Changes

This policy may be updated in line with the development of the Service and with legislation. Material changes are notified by email and/or within the Service before they take effect.

Effective date: August 6, 2026 · Last updated: August 6, 2026

[Ad Soyad / Ticaret Unvanı] · [Açık adres — mahalle, cadde, no, ilçe/il, posta kodu] · Türkiye · [email protected]